top | item 42158280

(no title)

claudiojulio | 1 year ago

I don't understand the issue with encrypted emails. Is Proton Mail not secure?

discuss

order

some_furry|1 year ago

"Is _____ not secure?"

What. is. your. threat. model?

palata|1 year ago

I genuinely wonder for ProtonMail (and anything web-based, really): isn't it a fact that if I use ProtonMail, my browser will download and execute a client every time? In the sense that I don't actually know what code my client is running. ProtonMail could totally decide to serve me a client that actually leaks data, and I would not know it unless I somehow save and audit the client every. single. time.

If I use e.g. Signal, I can of course build it from sources I trust, or download it from the Play Store and trust that Google won't send me a modified version of it (at least it seems less likely and harder to pull).

Am I wrong in considering that web-based clients cannot really be considered secure?

claudiojulio|1 year ago

Assuming full security, on Signal someone can also copy and paste my message, just as on Proton Mail they can forward it. I don't see any difference.